Fidelis Endpoint provides visibility, threat detection, and investigation capabilities for security operations. The solution serves as a component in incident response investigations, enabling organizations to prevent, detect, hunt, respond to, and resolve security incidents. Fidelis Endpoint captures kernel level events, process executions, registry changes, and network calls in real time. The solution monitors and evaluates endpoint events across Windows, Linux, and Mac systems to detect and stop attacks before lateral movement occurs. Features include automatic collection and correlation of related events, processes, and files, advanced queries with Boolean logic for detection and hunting, remote access to endpoint disk, files, and processes, and automated response processes such as endpoint isolation, memory analysis, and forensic collection. Upon detection, Fidelis Endpoint isolates compromised endpoints, quarantines files, collects forensic data, compares it against threat intelligence feeds and known vulnerabilities, and provides endpoint access. The solution protects endpoints off-network and responds to malicious activity while offline when threat detection rules are configured. The platform features automated detection and response capabilities that interact with Fidelis Network and Fidelis Deception for contextual visibility across network environments.